ondo.finance.eu.com
ondo.finance.eu.com — 最后已知的活跃状态 (HTTP 200). 证据摘要: VirusTotal 0/89; Spamhaus DBL_PHISH; PhishDestroy score 63/100. 注册商: Instra.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
证据摘要
ondo.finance.eu.com is a tenant hostname on Instra Corporation Pty Ltd., not a separately registered domain. PhishDestroy first observed the hostname on Sep 16, 2026. Current evidence score: 63/100 (high).
One source contains a positive finding: Spamhaus DBL. Spamhaus DBL: DBL_PHISH on Sep 21, 2026 at 10:30 UTC. Non-positive and contextual checks: VirusTotal recorded 0 detections among 89 engines on Sep 21, 2026 at 10:11 UTC. The separate external-blocklist snapshot contained no matches on Sep 21, 2026 at 10:20 UTC. The 0/89 VirusTotal snapshot and the positive findings above are conflicting observations from different sources or collection times.
HTTP 200 was recorded on Sep 16, 2026 at 17:28 UTC. Instra Corporation Pty Ltd. is the hosting platform for this tenant, not its registrar.
Neither a page title nor a landing-page capture is stored. Only one source contains a positive finding; no second positive source is stored. The stored fields do not identify an impersonated brand or victim interaction.
Forensic History & Detection Timeline
-
Threat First Observed Sep 21, 2026 · 12:03 UTCDomain ingestion complete. Initial state is marked as alive.
威胁响应 Pipeline
公共封禁名单状态
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not yet scanned
域名情报
技术详情DNS、SSL SAN、时间戳
VirusTotal 分析
社区情报
1 条社区报告
类别PHISHING
I got phished by a fake Ondo Finance website at ondo.finance.eu.com. It looked like the real thing, so I connected my wallet and signed what I thought was a normal transaction. Instead it drained about 791 USDC from my wallet on the Linea chain and split it between two wallets th
证据与外部报告
“I got phished by a fake Ondo Finance website at ondo.finance.eu.com. It looked like the real thing, so I connected my wallet and signed what I thought was a normal transaction. Instead it drained about 791 USDC from my wallet on the Linea chain and split it between two wallets the scammer controls: 0xff227Fef31C6e6D48EcD5eAB60B4e2bF32fC060d and 0xEE03FAb04D3cE3797022E48D3D1eE1F7d08c4778. The theft transaction is 0x0b97d1b52e9bc437dea50a2d0ef52cb0efeeb4d279f4f3ddbf70a355321b9514. The scam domain”
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。